Release Notes#
This document describes the new features and known issues for the NVIDIA Confidential Containers Reference Architecture.
1.1.0#
Release Date: August 11, 2026
This release expands hardware coverage and updates the validated software stack.
New Features#
Added support for the NVIDIA HGX B300 platform with both single-GPU and multi-GPU passthrough.
Added support for Ubuntu 26.04 as a host operating system.
Added support for the following software components:
Kata Containers 4.0.0
Kata Lifecycle Manager 0.1.8
containerd 2.3.x
This release has General Availability support for most platforms running Red Hat OpenShift Sandboxed Containers 1.13. Refer to Confidential containers: feature availability by OpenShift Container Platform version.
Docs Changelog#
The Install the Kata Containers Helm Chart procedure was updated for this release. Changes include:
Installs
kata-deploywith a values file instead of inline--setflags.Includes a new sample values file,
samples/kata-nvidia-gpu-values.yaml, that configures thekata-deployHelm chart for the NVIDIA Confidential Containers reference architecture (NVIDIA GPU shims only, NFD disabled,nydussnapshotter, and per-shim runtime class node selectors).Adds a readiness verification step using
kubectl rollout status ds/kata-deploy. This step relies on the readiness reporting in Kata Containers and lets you confirm thatkata-deployhas finished extracting artifacts and restarting containerd on every node before continuing.
Post-Release Documentation Updates#
Renamed the supported platforms page to Supported Platforms and Software Components.
Documented attaching a Kata agent security policy for attested production workloads. Refer to Attach a Kata Agent Security Policy.
Split the software matrix into cluster prerequisites, Kata-provided guest and runtime artifacts, and separately deployed components.
Recorded the distroless guest payload: NVRC, the NVIDIA GPU driver in the guest, and guest-components.
Updated the guest kernel and QEMU versions to match the Kata Containers artifacts this architecture installs.
Replaced the Key Broker Service protocol version with Trustee v0.21.0 as the separately deployed attestation component. The Attestation quickstart clones that Trustee tag, documents Compose image pins for KBS, AS, and RVPS to that commit, and pulls the matching
kbs-clientartifact.Pinned
genpolicyto 4.1.0 and pointed the download and README links at that Kata Containers release.Restored
--waiton the detailedkata-deployinstall command and attributed the disabled NFD deployment to the values file.Corrected the NFD setting in
samples/kata-nvidia-gpu-values.yaml. The sample used a key that thekata-deploychart ignores, so the chart default kept NFD disabled instead of the sample.
1.0.0#
Release Date: April 29, 2026
This is the initial general availability (GA) release of the NVIDIA Confidential Containers Reference Architecture, a validated deployment model for running GPU-accelerated AI workloads inside hardware-enforced Trusted Execution Environments (TEEs). It is designed for organizations in regulated industries that require strong isolation and cryptographic verification to protect model intellectual property and sensitive data on untrusted infrastructure.
The architecture combines NVIDIA GPU Confidential Computing, Kata Containers, and the NVIDIA GPU Operator to provide a secure, attestable, Kubernetes-native platform for confidential AI workloads.
Key Features#
This release supports HGX platforms with:
NVIDIA H100 (single-GPU passthrough)
NVIDIA H200 (single-GPU passthrough)
NVIDIA H100 Protected PCIe (multi-GPU passthrough)
NVIDIA H200 Protected PCIe (multi-GPU passthrough)
NVIDIA B200 (single-GPU and multi-GPU passthrough)
NVIDIA RTX Pro 6000 BSE (single-GPU passthrough)
AMD Genoa / Milan CPUs with Ubuntu 25.10 (kernel 6.17+) for SEV-SNP
Intel Emerald Rapids / Granite Rapids CPUs with Ubuntu 25.10 (kernel 6.17+) for TDX
This release supports the following software components:
NVIDIA GPU Operator v26.3.1
Kata Containers 3.29 (installed with the
kata-deployHelm chart)Kata Lifecycle Manager 0.1.4
Key Broker Service (KBS) protocol 0.4.0
QEMU 10.1 + Patches
OVMF edk2-stable202511
Containerd 2.2.2
Kubernetes 1.32+
Ubuntu 25.10 (host OS)
This release has Technology Preview support for Red Hat OpenShift Sandboxed Containers 1.12.
Limitations and Restrictions#
NVIDIA supports the GPU Operator and confidential computing with the containerd runtime only.
All GPUs on the host must be configured for Confidential Computing. Configuring only a subset of GPUs on a node is not supported. For multi-GPU passthrough, all GPUs must be assigned to a single confidential VM.
Early Access Release#
Release Date: December 22, 2025
The documentation for the early access release was published as part of the GPU Operator v25.10 release. Refer to Deploy Confidential Containers with NVIDIA GPU Operator.